<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: TLS trusted-host in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/tls-trusted-host/m-p/451992#M95660</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If it is the IDSM-2 certificate that expired, then the steps are correct.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My assumption, however, is that the error you are receiving is not because the IDSM-2 certificate has expired, but instead it is the VMS certificate that has expired.&lt;/P&gt;&lt;P&gt;You would need to create a new certificate for the VMS itself.  Then go to the sensor and remove the sensor's knowledge of the VMS old certificate and tell it to grab the new VMS certificate.&lt;/P&gt;&lt;P&gt;Here is how you tell the sensor to grab VMS's new certificate:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/univercd/cc/td/doc/product/iaabu/csids/csids11/cliguide/clitasks.htm#wp1036631" target="_blank"&gt;http://www.cisco.com/univercd/cc/td/doc/product/iaabu/csids/csids11/cliguide/clitasks.htm#wp1036631&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am not sure what the steps are to create a new certificate on the VMS itself.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 04 Aug 2005 21:22:47 GMT</pubDate>
    <dc:creator>marcabal</dc:creator>
    <dc:date>2005-08-04T21:22:47Z</dc:date>
    <item>
      <title>TLS trusted-host</title>
      <link>https://community.cisco.com/t5/network-security/tls-trusted-host/m-p/451991#M95658</link>
      <description>&lt;P&gt;Certificate on IDSM Console expired. Created new certificate, then deleted and add IDS Sensor using discovery. Login to IDS sensor verified clock on matched IDSM Console, then removed trusted-host and re-add to generate new certificate. Cert on sensor doesn't match IDSM Console cert. Still getting TLS trusted host errors when trying to do signature updates. Am I missing a step? Any suggestions? Thanks,  &lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 09:34:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tls-trusted-host/m-p/451991#M95658</guid>
      <dc:creator>vpoole</dc:creator>
      <dc:date>2019-03-10T09:34:18Z</dc:date>
    </item>
    <item>
      <title>Re: TLS trusted-host</title>
      <link>https://community.cisco.com/t5/network-security/tls-trusted-host/m-p/451992#M95660</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If it is the IDSM-2 certificate that expired, then the steps are correct.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My assumption, however, is that the error you are receiving is not because the IDSM-2 certificate has expired, but instead it is the VMS certificate that has expired.&lt;/P&gt;&lt;P&gt;You would need to create a new certificate for the VMS itself.  Then go to the sensor and remove the sensor's knowledge of the VMS old certificate and tell it to grab the new VMS certificate.&lt;/P&gt;&lt;P&gt;Here is how you tell the sensor to grab VMS's new certificate:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/univercd/cc/td/doc/product/iaabu/csids/csids11/cliguide/clitasks.htm#wp1036631" target="_blank"&gt;http://www.cisco.com/univercd/cc/td/doc/product/iaabu/csids/csids11/cliguide/clitasks.htm#wp1036631&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am not sure what the steps are to create a new certificate on the VMS itself.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Aug 2005 21:22:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tls-trusted-host/m-p/451992#M95660</guid>
      <dc:creator>marcabal</dc:creator>
      <dc:date>2005-08-04T21:22:47Z</dc:date>
    </item>
    <item>
      <title>Re: TLS trusted-host</title>
      <link>https://community.cisco.com/t5/network-security/tls-trusted-host/m-p/451993#M95661</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for your response. I believe you're correct about it being VMS cert. Used keytool -printcert -file ./server.cert to veiw newly created cert, which is now good for 10 years. Already tried your suggestion of removing VMS trusted-host on sensor and then adding it back to create a new cert. &lt;/P&gt;&lt;P&gt;"no TLS trusted-host ip-address 172.16.208.50"&lt;/P&gt;&lt;P&gt;TLS trusted-host ip-address 172.16.208.50"&lt;/P&gt;&lt;P&gt;It adds VMS ip address to trusted host list, but creates a cert that doesn't match new cert, so it's not grabing the new cert from VMS for some reason. I'm wondering if there is a communication problem between sensor and vms host? However, I can delete sensor and then add sensor back using discovery mode without problems. Open to additional suggestions since I'm still at a lost.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Aug 2005 11:45:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tls-trusted-host/m-p/451993#M95661</guid>
      <dc:creator>vpoole</dc:creator>
      <dc:date>2005-08-05T11:45:46Z</dc:date>
    </item>
    <item>
      <title>Re: TLS trusted-host</title>
      <link>https://community.cisco.com/t5/network-security/tls-trusted-host/m-p/451994#M95662</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There was a defect affecting IDS MC versions 2.0 and 2.0.1 that would cause the behavior you are seeing if you are using the CiscoWorks certificate.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you are running an affected version, go into VPN/Security Management Solution &amp;gt; Administration &amp;gt; Configuration &amp;gt; Certificate. If the "CiscoWorks Certificate" is selected, then this is your problem. The following link provides two workarounds.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/cgi-bin/Support/Bugtool/onebug.pl?bugid=CSCsa53069" target="_blank"&gt;http://www.cisco.com/cgi-bin/Support/Bugtool/onebug.pl?bugid=CSCsa53069&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Aug 2005 15:44:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tls-trusted-host/m-p/451994#M95662</guid>
      <dc:creator>brhamon</dc:creator>
      <dc:date>2005-08-08T15:44:34Z</dc:date>
    </item>
    <item>
      <title>Re: TLS trusted-host</title>
      <link>https://community.cisco.com/t5/network-security/tls-trusted-host/m-p/451995#M95663</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for your response. It appears old cert was being cache somewhere. Once I stopped and started crmdmgtd service, sensors were able to grab new cert.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Aug 2005 16:05:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tls-trusted-host/m-p/451995#M95663</guid>
      <dc:creator>vpoole</dc:creator>
      <dc:date>2005-08-08T16:05:03Z</dc:date>
    </item>
  </channel>
</rss>

